MeterSphere Logic Flaw in User Authentication Allowing Arbitrary User Login

Vulnerability

A logic flaw has been identified in MeterSphere, an open-source continuous testing platform, prior to version 2.10.25-lts. This vulnerability allows an unauthenticated attacker to log in as any user by exploiting a flaw that permits the retrieval of arbitrary user information. The issue arises from the application's trust in the authentication method specified by the user, which can be manipulated to bypass authentication checks. The vulnerability has been patched in version 2.10.25-lts.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts, potentially leading to unauthorized actions within the application on behalf of the impersonated user.

Reproduction

To reproduce this vulnerability, send a POST request to the '/signin' endpoint with a username, a password set to false, and an authentication method of 'LDAP'. This request will bypass the normal authentication process and log in as the specified user.

Remediation

Users can upgrade to MeterSphere version 2.10.25-lts or later to address this vulnerability.

Added: Oct 22, 2025, 3:26 PM
Updated: Oct 22, 2025, 9:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
1.3
exploitability
7.6
remediation
7.7
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.